merfin993

Results 5 comments of merfin993

@doomedraven Hi, I'm luca the colleague of simone.co. I apologize for the delayed reply. We tried to do some debugging and all signatures seem to be running correctly. (the conditions...

Hi @hasherezade, thanks for the reply. The setting that doesn't run the payload with Tiny_Tracer (vmprotect demo latest version) ![debugger](https://user-images.githubusercontent.com/108698184/209724780-2656a590-1d4d-4c2b-9840-8b443303ed4b.PNG) And the sample [sample.zip](https://github.com/hasherezade/tiny_tracer/files/10310845/sample.zip) (Password "infected") You will find the...

Hi @hasherezade. Today I was able (with a driver) to get trace of system calls used by vmprotect with usermode and usermode + kernelmode antidebug flags enabled. I wanted to...

Hi @hasherezade. I did some tests by disabling virtualization and mutations to get the cleanest trace possible. (the sample is contained in the archive) Using a driver to get syscall...